VMware / Spring Cloud Config
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59315 | Spring Cloud Config Monitor Denial of Service | MEDIUM | 5.3 | Aug 27, 2026 |
| CVE-2026-47894 | Spring Cloud Config Server Native Environment Repository Exposure | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-47837 | Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests | CRITICAL | 9.8 | Aug 26, 2026 |
| CVE-2026-47836 | Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN | HIGH | 8.1 | Aug 26, 2026 |
| CVE-2026-40981 | Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-41002 | The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-che… | HIGH | 8.1 | May 7, 2026 |
| CVE-2026-41004 | Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging | MEDIUM | 4.4 | May 7, 2026 |
| CVE-2026-40982 | Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access | CRITICAL | 9.1 | May 7, 2026 |
| CVE-2026-22739 | Spring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable SSRF Attacks | HIGH | 8.6 | Mar 24, 2026 |
| CVE-2023-20859 | In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive inf… | MEDIUM | 5.5 | Mar 23, 2023 |
| CVE-2020-5410 KEV | Directory Traversal with spring-cloud-config-server | HIGH | 7.5 | Jun 2, 2020 |
| CVE-2020-5405 | Directory Traversal with spring-cloud-config-server | MEDIUM | 6.5 | Mar 5, 2020 |
| CVE-2019-3799 | Directory Traversal with spring-cloud-config-server | MEDIUM | 6.5 | May 6, 2019 |
Showing 1 to 13 of 13 CVEs